发明名称 SECURED NETWORK ARCHITECTURE
摘要 A secure storage for an X.509v3 digital certificate is provided (301, 302). Ports of a first and second apparatus (101, 102) are mutually authenticated (303) by using 802.1X based authentication and 802.1AR certificates. Traffic types are divided (304, 305) by an operator-configurable selector function into user plane, control plane, synchronization plane, and management plane traffic types. For Ethernet transport a virtual port is created for each traffic type, and a different MACsec secure connectivity association is created for each virtual port. For Ethernet transport an operator-programmable security policy is maintained for each traffic type. For IP transport an IPsec security association is created for each traffic type, and an operator-programmable security policy is maintained for each security association. For IP transport, TLS support may be enabled for compatibility with network management traffic. A port is repeatedly re-authenticated by an operator- definable timer value.
申请公布号 WO2014154264(A1) 申请公布日期 2014.10.02
申请号 WO2013EP56541 申请日期 2013.03.27
申请人 NOKIA SOLUTIONS AND NETWORKS OY 发明人 METSALA, ESA MARKUS;ALMAY, HEIKKI-STEFAN
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址